当前位置: X-MOL 学术Wireless Pers. Commun. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
A Novel Feature-Based DDoS Detection and Mitigation Scheme in SDN Controller Using Queueing Theory
Wireless Personal Communications ( IF 1.9 ) Pub Date : 2021-01-04 , DOI: 10.1007/s11277-020-07954-3
Ava Tahmasebi , Ahmad Salahi , Mohammad Ali Pourmina

Software defined network (SDN) has attracted great interests as an emergent paradigm which aims to centralize the configuration of network devices by decoupling control layer and data layer. One considerable challenge in SDN is to protect against multiple attacks generated by distributed denial of service (DDoS) bots which attempt to make SDN controllers unavailable. The goal of this research is to propose a novel detect and mitigate DDoS attack in SDN controllers using traffic monitoring. Besides the advantages of queueing theory based model is exploited to evaluate the arrival flows and leveraging robust features and entropy, a distance-based classification is designed accurately to detect malicious packets from legitimate packets. The experimental results vividly demonstrate that our proposed detection scheme effectively yields high accuracy as well as high-efficiency controller utilization.



中文翻译:

基于排队论的SDN控制器中基于特征的新型DDoS检测与缓解方案

作为一种新兴的范例,软件定义网络(SDN)引起了人们的极大兴趣,该范例旨在通过解耦控制层和数据层来集中化网络设备的配置。SDN中的一大挑战是防止分布式拒绝服务(DDoS)僵尸程序产生的多种攻击,这些攻击试图使SDN控制器不可用。这项研究的目的是提出一种使用流量监控的新型检测和缓解SDN控制器中的DDoS攻击的方法。除了利用基于排队论的模型的优势来评估到达流并利用鲁棒的特征和熵之外,还可以精确设计基于距离的分类,以从合法数据包中检测恶意数据包。

更新日期:2021-01-04
down
wechat
bug